Can I configure this PIX 515E without failover? Also, why the ip assignment problem?

We have acquired a

"PIX 515E FO-AA BUN-sw Act/ac Tfo License Vac+ 6fe"

firewall and I am having trouble configuring it as a primary. Is it even possible to configure it as the primary (and ultimately the only) firewall?

The difficulties I'm having seem to revolve around my inability to assign the inside interface an IP address. Using the CLI, I go into configure mode for the interface and give it "ip address 192.168.1.1 255.255.255.0 inside" and the command completes with no errors reported yet when I "show interface", it reports the inside interface as having no IP address assigned.

BTW, if I use the CLI to "configure factory-default" then "show interface", it does assign the inside interface an IP and I'm able to use ASDM successfully which is very strange to me. Despite using "write memory" to save that working configuration to the flash, rebooting the firewall reloads a non functioning config giving me the same problem I described above.

Even running the "setup" command and assigning the IP address that way fails to actually assign it. The ONLY way I can get it to work is through loading the factory-defaults.

Your help is GREATLY appreciated!
madabdul82Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

imreble1Commented:
FYI
We tried setting up a pix with a failover license as a stand alone. We got the ip address to take but without its partner in crime it will not ARP.


RDC
Fishnet Security
 



0
minmeiCommented:
A PIX with a failover license will not work by itself - the failover license is the cheapest one to get, because it is only used for the 2nd PIX in a failover pair - the primary uses an unrestricted license (most costly) and the secondary can run on an FO license.

You will need to but at least a restricted license to run your PIX.

0
stressedout2004Commented:
Although not recommended, a PIX with a FO or FO-AA license can function as a standalone unit but will reboot at least once every 24 hours until you returned it to its proper function. I had customers who ran their firewall as a standalone using FO licenses but they eventually bought the proper license. Just don't forget to run the command "failover active" (even not using a failover configuration). This command is necessary to get the firewall running as standalone.

When you do the command "configure factory-default", the PIX does the following:

The default factory configuration for the PIX 515/515E security appliance configures the following:

1) E1 (inside) interface will have the IP address 192.168.1.1 and mask of 255.255.255.0.

2) DHCP server will be enabled in the range of 192.168.1.2 to 192.168.1.254. So any PC connecting to the internal network should get an IP address from the PIX.

3) HTTP server (192.168.1.1) will likewise be enabled for ASDM and should be accessible from the 192.168.1.0/24.

So by factory default config, you should already have an IP address assigned on the E1 of the PIX which is 192.168.1.1. Unless you want to change that, then thats the time you should go to the interface config mode.

If you want to change the IP address of the PIX, here's what I would advice you to do.

1) First do the command "failover active"
2) Then go to interface configuration mode and make the neccessary changes:

e.g.

interface ethernet1
 ip address 10.1.1.1 255.255.255.0
 nameif inside
 no shut

3) Save it to memory using the command: "copy running-config startup-config"


0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
madabdul82Author Commented:
Thank you for the concise answer, stressedout2004! Basically its fooling the PIX into thinking it's counterpart is malfunctioning...but the joke is really on me.

I will be acquiring the correct licensing for this PIX to run as a primary and I very much appreciate both you and the administrator cautioning me on that.

Thanks again!
0
Keith AlabasterEnterprise ArchitectCommented:
I'm pleased you took the comment the way it was meant and you have the information you need.

regards
keith
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.